Privacy Policy
Effective date: 20 July 2026
Last updated: 20 July 2026
1. Who we are
NightDraft is a software product operated by Freddie Chambers, trading as NightDraft (a sole trader established in the United Kingdom) ("NightDraft", "we", "us", "our"). NightDraft helps restaurant owners draft replies to inbound booking enquiries in their own voice, and is accessible at nightdraft.com. Our hosting and data-storage arrangements are described in sections 8, 10 and 13.
Contact for privacy questions: privacy@nightdraft.com
Contact for security issues: security@nightdraft.com
2. What this policy covers
This policy explains how NightDraft handles data when a restaurant owner connects their Google account to NightDraft. It covers:
- The data we receive from Google APIs (Gmail content)
- How that data is used to draft replies
- How long we keep it
- Who can access it
- How an owner can delete it
It does not cover anything done outside the NightDraft application.
3. The Google data we access
When a restaurant owner authorises NightDraft, we request exactly two OAuth scopes from Google:
https://www.googleapis.com/auth/gmail.readonly(classified by Google as a restricted scope) - lets NightDraft read the body of inbound emails in the connected mailbox so it can identify booking enquiries and extract context for the draft replyhttps://www.googleapis.com/auth/gmail.drafts.create(classified by Google as a sensitive scope) - lets NightDraft create a draft reply in the connected mailbox's Drafts folder, attached to the original thread, for the owner to review and send
We do not request gmail.send, gmail.modify, gmail.compose, or mail.google.com. We cannot send messages from a connected account. We cannot delete or modify messages other than drafts we have created. We cannot change account settings.
4. Limited Use - Google API Services User Data Policy
NightDraft's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice this means:
- We only use the Gmail data we receive to provide the user-facing feature the owner authorised (drafting replies to booking enquiries in their voice)
- We do not transfer Google user data to third parties except as necessary to provide and improve the feature the owner authorised, or to comply with applicable law, or as part of a merger, acquisition, or sale of assets where the new owner is bound by commitments at least as protective as those in this policy
- We do not use Google user data for advertising purposes
- We do not use Google user data, including for training, to develop, improve, or train generalised or general-purpose AI or machine-learning models
- We do not allow humans to read Google user data except (a) with the owner's explicit consent for specific messages, (b) where necessary for security or to debug an issue affecting their account (with the owner's consent where practicable), or (c) to comply with applicable law
5. The exact data path
When a booking enquiry arrives at a connected mailbox:
- Read. NightDraft fetches the message body via the Gmail API using the
gmail.readonlyscope - Process transiently. The message body is sent to an AI provider (currently Anthropic's Claude API) along with the restaurant's playbook so a draft reply can be composed. This is a transient API call; the message is not stored on Anthropic's side beyond the duration of the API call
- Draft. NightDraft creates a draft reply in the connected mailbox's Drafts folder, attached to the original thread, using the
gmail.drafts.createscope - Owner review. The owner opens their Gmail Drafts folder, reads the draft, edits it freely, and sends it themselves. NightDraft has no send capability
- Retain the operational record. NightDraft stores the inbound message, the draft it generated, and operational metadata (sender domain, timestamps, scope-usage logs) in its database while your account is active, so the owner can review drafts, so the service can improve the quality of future drafts, and so we can debug and audit the service. You can have any stored item deleted at any time on request (see section 9), and all stored data is deleted within 30 days of you revoking access.
6. Retention
NightDraft retains booking data while your account is active, so the service can improve the quality of future drafts and so disputes can be audited. The position is:
| Data | Retention | Purpose |
|---|---|---|
| Message bodies of inbound enquiries | Retained while your account is active; deleted within 30 days of you revoking access, or sooner on request | Generate the draft; improve future draft quality; audit disputes |
| Generated draft bodies | As above | Owner review; improve future draft quality; audit |
| Operational metadata (sender domain, timestamps, scope usage) | As above | Debugging, security audit, dispute resolution |
| OAuth tokens | Until you revoke consent or NightDraft is uninstalled | Maintaining the connection |
You can have any specific item deleted at any time on request (see section 9), and all stored data is deleted within 30 days of you revoking access. We do not retain "aggregated and anonymised statistics" today; if we introduce them we will update this policy first.
7. AI usage disclosure
NightDraft uses Anthropic's Claude API to draft replies. We send the following to Anthropic for each draft:
- The booking enquiry's message body
- The restaurant's playbook (voice templates, pricing language, cancellation policy)
- A system prompt describing the desired output format
Anthropic processes this transiently to generate the draft. Per Anthropic's published commercial terms, inputs submitted through the API are not used to train Anthropic's models; Anthropic retains limited metadata for abuse-prevention purposes for a limited period, but not the prompt content. We do not train any AI or machine-learning model on customer Gmail data.
8. Sub-processors
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Google (Gmail API) | Source of inbound mail; destination for drafts | Authorised by the owner |
| Anthropic (Claude API) | Draft generation | Message body + playbook, transient |
| Railway (application hosting and database) | Runs the NightDraft application and stores its operational database | Inbound message bodies, generated drafts, and operational metadata (per section 6) |
| Netlify (website hosting) | Hosts the NightDraft homepage and this policy | None - no Gmail data |
This list will be updated as the product evolves. Material changes will be announced to current customers via email.
9. Owner rights
The owner of a connected mailbox can:
- Revoke consent at any time from their Google Account at myaccount.google.com/permissions. NightDraft loses access immediately. Existing stored data is deleted within 30 days.
- Request deletion of specific items by emailing privacy@nightdraft.com. We respond within 7 days.
- Request export of stored data by emailing privacy@nightdraft.com.
- Receive a copy of edit-log entries we have stored about their drafts on request.
Diners whose emails are read (the senders of the inbound enquiries) do not have a direct relationship with NightDraft, but if they email privacy@nightdraft.com requesting deletion of an item about them, we will action that within 7 days.
10. Security
- All Gmail data is transmitted over HTTPS (TLS 1.2 or higher) on every external connection
- The NightDraft application and its database run on Railway, a managed cloud platform, on a private volume that is not exposed to the public internet. The application has no public login page, no public website, and no inbound API
- Access to the operational database and OAuth tokens is restricted to the NightDraft operator; tokens are not transmitted to any third party other than Google
- The application requests only two Gmail scopes (read and create-draft); it cannot send, modify, or delete mail, which limits the impact of any compromise
- The NightDraft website (nightdraft.com) is served over HTTPS with Content Security Policy and HTTP Strict Transport Security headers
- Security issues can be reported to security@nightdraft.com
11. Dietary and allergy information
Inbound booking enquiries occasionally mention a dietary or allergy requirement. In the bookings NightDraft handles, this is almost always a group booking where the requirement concerns an unnamed member of the party (for example, "one of our guests is coeliac") rather than the person sending the email. As such, this information is generally not linked to an identified or identifiable individual, and so does not typically constitute "special category" personal data under UK and EU data-protection law.
Regardless, we handle it carefully:
- We do not ask for it; it arrives only because the sender chose to include it in an email to the restaurant. We process it solely to help the restaurant owner draft an appropriate reply
- The restaurant owner has the direct relationship with the diner and remains responsible for how they use the information in their reply
- NightDraft's drafting process is designed to flag emails containing serious allergy signals for the owner's attention rather than auto-answering them
- Where such information is, in a given case, linked to an identifiable individual, we treat it as special category data. Our lawful basis is the restaurant owner's explicit consent, given when they connect their Google account in the knowledge that inbound booking emails may contain such information, together with the necessity of processing it to provide the drafting service they have requested (UK GDPR Article 9(2)(a) explicit consent, with Article 6(1)(b) contract necessity). We retain and delete it on the same basis as other message content (sections 6 and 9)
If you would like any such information about you deleted, email privacy@nightdraft.com and we will action it (see section 9).
12. Children's data
NightDraft is a B2B product. We do not knowingly process data of children under 16. If you believe we have, contact privacy@nightdraft.com.
13. International transfers
NightDraft is operated from the United Kingdom, but its application and database are hosted with Railway in the United States, and draft generation uses Anthropic's API, which is also hosted in the United States. This means inbound message content and the operational records described in section 6 are stored and processed in the United States. Where personal data is transferred from the UK/EEA to the United States, we rely on the UK International Data Transfer Agreement / the EU Standard Contractual Clauses (and, where applicable, the EU-US Data Privacy Framework and its UK Extension) as the transfer mechanism with our sub-processors. You can contact privacy@nightdraft.com for more detail on the safeguards in place.
14. Changes to this policy
We will announce material changes by email to current customers at least 30 days before they take effect. Cosmetic changes (typo fixes, link updates) may be made without notice. The current version is always at nightdraft.com/privacy with a "Last updated" date at the top.
15. Complaints
If you believe NightDraft has mishandled Gmail data, please email privacy@nightdraft.com first so we can investigate. If you are unsatisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk.
16. Contact
Freddie Chambers, trading as NightDraft (a sole trader established in the United Kingdom).
The fastest way to reach us is by email:
Email: privacy@nightdraft.com (privacy and data requests)
Email: security@nightdraft.com (security)
Email: hello@nightdraft.com (general)
A postal address is available on request by emailing privacy@nightdraft.com.
← Back to NightDraft